Open-source project
change-42-yhmm/quota-float avatar
change-42-yhmm/quota-float

Quota Float reads your Codex Desktop session and refuses to estimate when it cannot know

A lightweight Windows/macOS desktop widget that keeps your Codex quota visible from your local Codex Desktop session.

365 stars25 forksRustMIT

At a glance

What is it?
A Tauri widget for Windows and macOS that shows five-hour and weekly quota for Codex and Claude subscriptions plus API spend for OpenAI and Anthropic, from login state already on your machine. It stores preferences only, sends your token only to quota endpoints, and shows an unavailable state rather than a made-up number.
Who is it for?
Adopt Quota Float if you use Codex or Claude subscriptions on Windows or macOS and want remaining quota visible without opening a dashboard, and you are comfortable with a second application reading an existing login session to do it.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 12 days ago.
What is it written in?
Mainly Rust, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 2, 2026, and from our analysis. They are not legal advice.

Editorial analysis

It reuses the Codex Desktop session and sends the token only to quota endpoints

The mechanism is narrow on purpose, and the README states it in the plainest terms available. Quota Float reads the existing Codex Desktop login state on your machine and queries the Codex and ChatGPT quota endpoints with that session. There is no second login, no API key entry, and no account configuration step.

What it will not do is as specific as what it will. It does not estimate usage from local token counts, so the number on screen is never a guess derived from something the app happens to see. It does not redeem reset credits and it does not modify account settings. Both exclusions matter, because a quota widget that could top up your own limit would be a different kind of program.

The privacy boundary is enumerated rather than summarised. The local Codex Desktop login state is read only to query Codex quota. The existing Codex access token goes only to ChatGPT quota endpoints. The app stores only its own widget preferences in its own app config directory. It does not store Codex tokens, account IDs, prompts, chat history, raw quota responses or local auth paths. There is no telemetry, no analytics, no crash reporting and no third-party tracking. PRIVACY.md and SECURITY.md hold the full boundary.

The accuracy boundary closes the loop. Codex quota comes from the quota service responses themselves, and if that response format changes the app shows an unavailable or stale state instead of inventing quota values. Stale data, signed-out sessions, unavailable responses and loading states are all named as handled cases.

One tray number means different things depending on which source you select

Four sources are supported and they do not report the same kind of quantity. A subscription source, meaning Codex and ChatGPT quota or Claude subscription quota, reports a five-hour window and a weekly window with the next reset time. An API source, meaning OpenAI API costs or Claude API costs, reports current spend as an amount with its currency.

That difference is why the widget carries provider-specific marks and presentation, so a percentage of a subscription is never confused with a figure in dollars. You can switch the visible provider from the widget itself, and it can rotate between connected sources automatically, so a single glance can cycle through everything you pay for.

The native status area is where the compact reading lives: a small number in the Windows tray icon, or an optional macOS menu-bar readout. The tray icon shows the selected provider's current metric, and when API spend is available that is what it shows, otherwise it shows the remaining five-hour quota. Both are marked as using mock quota data in the previews.

The states are three and named: healthy, caution and critical remaining usage. The widget also indicates whether quota is currently being consumed, so a moving number is not mistaken for a stuck one, and when the five-hour window is unavailable it falls back to a clearly marked weekly-quota view rather than showing nothing at all.

In a browser you get mock data, so the desktop app is not optional

The most important limitation is stated early and it decides who can use this. Browser preview uses mock data. Real quota reading requires the Tauri desktop app and an existing Codex Desktop login on the same machine.

So the web build is a design and layout surface, not a monitoring tool. If you open the project in a browser expecting your real quota, you will get plausible numbers that mean nothing, which is also why the README repeats that the screenshots and every skin preview use mock quota data only and contain no account, device or licence information.

The same-machine requirement is the second constraint. The widget reads login state that lives on the machine where Codex Desktop is installed and logged in, so this is not something you put on a remote box to watch a quota you use somewhere else.

What you get on the installed app, for the record: a small floating orb when idle that expands on hover, persistent expansion so it stays open, always-on-top controls, localized tray actions, and reset-credit count and expiration times shown when the quota service provides them.

The widget is for one person at one desk. There is no shared view, no team dashboard and no history, because the privacy boundary rules out storing what it reads.

Updater artifacts are signed; Authenticode and notarization are separate steps you may be missing

The signing story has two layers and the README separates them, which is the right thing to do and also a warning.

Updater artifacts are signed with the project's Tauri update key, so the app can verify and apply an update by itself. Windows Authenticode signing and macOS notarization are separate platform-signing steps. Builds without those certificates may still trigger SmartScreen or Gatekeeper warnings.

That sentence covers the case most people hit on first run. An installer can be correctly signed for the updater and still be unsigned as a desktop application, which means Windows SmartScreen or macOS Gatekeeper may warn you about an executable you actually downloaded from the project's own release page. The fix is not in the application; it is in the certificates the build was made with.

The same split shows up in the build instructions. On Windows, Tauri may download WiX to create an MSI installer, and if that download fails the release executable may still be produced at a fixed path.

text
src-tauri/target/release/quota-float.exe

That fallback is worth knowing before you debug an MSI build, because the executable existing at that path does not mean the installer was created.

The current public release is v0.2.12, offered as a Windows setup executable, a Windows MSI, and a macOS Universal disk image covering Apple Silicon and Intel.

A Codex Desktop update is a maintenance event, and the check script is PowerShell

The widget depends on another application's internals, so it has a maintenance ritual that most desktop apps do not.

After Codex Desktop updates, run the compatibility check.

bash
npm run check:codex

That maps to a PowerShell invocation of scripts/check-codex-update.ps1 in the package manifest, and docs/CODEX-UPDATE-CHECK.md documents the automated update-check workflow with optional Task Scheduler setup. So the intended operating mode is not manual verification but a scheduled check, and the documentation says so.

The PowerShell detail is a real portability wrinkle rather than a cosmetic one. The check script is a .ps1 file wired into an npm script, so running it on macOS requires PowerShell to be present even though the app itself is delivered as a Universal disk image for both architectures.

The build side is conventional Tauri. Development needs Node.js 20 or newer, Rust stable, and the Tauri 2 system dependencies for your platform.

bash
npm install
npm run dev
npm run test
npm run build
npm run tauri dev

and a production build is npm run tauri build. The manifest version is 0.2.12, matching the release, and the project is marked private with an MIT licence.

Supporter skins are device-bound, signed, and verified without phoning anywhere

The optional appearances are the monetisation, and their licence design is the interesting part rather than the price.

The standard installer includes the free default appearances and can unlock optional supporter skins with a signed, device-bound license. Licenses are verified locally, and the app does not send device request codes or license text to a service. A device-bound key checked on the machine means the verification path never needs a phone-home, which is consistent with the rest of the privacy boundary.

The skins themselves are cosmetic variants: Glass is a translucent frosted treatment, Nexus is a mechanical futuristic frame, and Blur and Computer are the two named supporter appearances. Every preview uses mock quota data and, by the README's own statement, reveals no account, device or licence information.

One upgrade behaviour is worth knowing because it will surprise people. Version 0.2.10 opens the supporter panel on the first two launches after an upgrade, while preserving existing local licenses and preferences. So an upgrade can interrupt you with a panel twice, and your unlocks survive it.

The repository also carries design-qa.md and a CONTRIBUTING.md at the root, plus assets/ and tools/, which is more design and process documentation than a two-platform tray widget strictly needs.

The build checks its own release assets, and CI produces installers on every tag

Two things in package.json reveal how the project keeps itself honest.

The build script is not just a bundler. It runs tsc, then vite build with the native config loader, then node scripts/check-release-assets.mjs, which is a release-asset check bolted onto the end of a normal build. A build that produced the wrong files fails before it can be published.

The test script is vitest run against the same native loader, and the dev dependencies show what kind of tests are written: @testing-library/react and jest-dom with jsdom, which means component tests in a simulated DOM rather than Rust-side tests alone.

The runtime side is small and mostly Tauri plumbing: @tauri-apps/api at 2.8.0, plugin-opener, plugin-process and plugin-updater at 2.10.1, plus @phosphor-icons/react for the icon set and React 19.1.1 on the front end. The Rust side lives in src-tauri.

Continuous integration is configured for two triggers. On push and pull requests it runs frontend tests, Rust tests, the web build and a Tauri build, so a broken Rust side is caught even though the JavaScript suite would pass. On v* tags it produces the Windows installer, the macOS Universal installer, the updater signatures, latest.json and a public GitHub Release, which is exactly the set the in-app updater needs.

Release cadence is steady rather than fast: v0.1.5 on 2026-07-13, v0.2.4 on 2026-07-22, v0.2.12 on 2026-09-21.

Editorial conclusion

Adopt Quota Float if you use Codex or Claude subscriptions on Windows or macOS and want remaining quota visible without opening a dashboard, and you are comfortable with a second application reading an existing login session to do it. Do not adopt it if you cannot accept that, because reading the Codex Desktop login state is the whole mechanism and the privacy boundary depends on trusting it, nor if you want a record of your usage history, since nothing is stored beyond widget preferences. Verify three things first: that your Codex Desktop login is on the same machine as the widget, since the browser preview shows mock data instead of real quota, whether your platform build carries Authenticode or notarization certificates or you will meet a SmartScreen or Gatekeeper warning, and that npm run check:codex passes after a Codex Desktop update. The licence is MIT, version 0.2.12 shipped on 2026-09-21, and the last push was on that date.

Frequently asked questions

How does Quota Float know my Codex usage?

It reads the existing Codex Desktop login state on your machine and queries the Codex and ChatGPT quota endpoints with that session. It does not estimate usage from local token counts, does not redeem reset credits and does not modify account settings.

What data does Quota Float store on my computer?

Only widget preferences, in its own app config directory. It does not store Codex tokens, account IDs, prompts, chat history, raw quota responses or local auth paths, and it includes no telemetry, analytics, crash reporting or third-party tracking.

Can I see my real quota in the browser version?

No. Browser preview uses mock data, and every screenshot and skin preview in the documentation uses mock quota data as well. Real quota reading requires the Tauri desktop app with an existing Codex Desktop login on the same machine.

Why does the Quota Float installer trigger a Windows or macOS warning?

Updater artifacts are signed with the project's Tauri update key, but Windows Authenticode signing and macOS notarization are separate platform-signing steps. Builds without those certificates may still trigger SmartScreen or Gatekeeper warnings.

Official sources

  1. change-42-yhmm/quota-float on GitHub
  2. Issues
  3. License: MIT
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/change-42-yhmm-quota-float.svg)](https://hysenlabs.com/projects/change-42-yhmm-quota-float)